1 to 25 of 224 Incident Response Jobs in the UK excluding London

Principal Consultant - Incident Response

Hiring Organisation
Circle Recruitment
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£65,000 - £85,000 per annum
Principal Consultant - Incident Response Salary: Up to £85,000 + cash benefits Location: London, Cardiff, Manchester, Birmingham or Edinburgh Working pattern: Hybrid - 2-3 days per week in the office About the Role Our client is seeking an experienced Principal Consultant to join their Incident Response practice. This is a senior, client-facing role within a highly regarded cyber security team, delivering proactive incident readiness engagements. You will work closely with organisations to strengthen their preparedness. This includes reviewing and developing incident response plans, facilitating tabletop exercises, running simulated attack scenarios ...

Incident Response Manager

Hiring Organisation
Proactive Appointments
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £110,000 per annum
Incident Response Manager Hybrid We are partnering with a leading global financial services organisation to appoint a Incident Response Manager to join their high-profile Cyber Threat Centre (CTC). This is a critical leadership role at the forefront of defending against sophisticated cyber adversaries, including … nation states and organised criminal groups. As the central hub for Computer Network Operations, the CTC drives incident response, threat hunting, intelligence, and insider threat detection across the organisation. This role offers the opportunity to shape strategy, lead a globally distributed team, and work with cutting-edge technologies ...

Cyber Incident Response Manager

Hiring Organisation
Ashdown Group
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £120,000 per annum
Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber threat … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

Cyber Security Incident Manager

Hiring Organisation
Ashdown Group
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £120,000 per annum
Security Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

IT Security Incident Manager

Hiring Organisation
Ashdown Group
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £120,000 per annum
Security Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

Cyber Incident Response Analyst

Hiring Organisation
Lorien
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£300 per day
Cyber Incident Response Analyst London - Onsite 2/3 days a week ASAP Start - November 26 £300 per day - Inside of IR35 We are looking for a Cyber Incident Response Analyst to join a small, highly visible cyber security team and step in for an existing … another project for the next 6-9 months. This role sits on the "Respond" side of Cyber Security, focusing on end-to-end cyber incident management, stakeholder communications, and clear reporting. With increased workload driven by the client merger, this is a key role supporting the organisation's security ...

IT Security Analyst – Incident Response & Vulnerability Management

Hiring Organisation
Operations Resources
Location
Cardiff, South Glamorgan, Wales, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Title Level 3 Security Analyst – Incident Response & Vulnerability Management Department Service Delivery/Security Reporting To Security Lead/Service Delivery Manager Operates under the direction of the Incident Manager during security incidents Location UK (Hybrid) Office in Cardiff 1-2 days per week, regular client site … travel. Working Pattern Monday to Friday with participation in the on-call Security and Major Incident rota as required Role Purpose The Level 3 Security Analyst is responsible for the technical investigation, containment, remediation, and resolution of IT security incidents and vulnerabilities across a complex, multi-site customer estate ...

Cyber Security Operations Manager

Hiring Organisation
Acorn Insurance
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£75,000
lead the operational security function responsible for protecting the organisation's information assets, technology services, and users. This role oversees all security operation functions, incident response, threat detection, vulnerability management, and continuous improvement of the organisation's security posture. Working closely with Infrastructure, Cloud, Architecture, Governance, Compliance … manage the daily operations of the internal Security Operations team and primary relationship with any outsourced SOC solution ensuring 24/7 monitoring and response coverage. Oversee cyber defence capabilities including SIEM, SOAR, EDR/XDR, threat intelligence, and identity protection. Develop and maintain operational procedures, playbooks, and response ...

Security Operations Team Lead

Hiring Organisation
Forward Role
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
ensuring the organisation's systems, networks, and data remain protected against evolving cyber threats. As the SecOps Lead, you will manage security monitoring and incident response activities while providing strategic direction for security tools including SIEM and Endpoint Detection & Response (EDR) platforms. You will work closely with … daily operational activities and performance. Define and implement the strategy and operational roadmap for security monitoring, detection, and response. Own and manage the security incident response lifecycle, including investigation, containment, remediation, and post-incident reviews. Lead incident response efforts during high-severity security events ...

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

SOC Analyst - 24/7 Secure Operations (Public Sector)

Hiring Organisation
Hays Specialist Recruitment Limited
Location
Winchester, Hampshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
£250 - £300 per day
such as QRadar, Microsoft Sentinel and LogRhythm, identifying and responding to threats, investigating and triaging incidents, and escalating where appropriate. You'll contribute to incident response activities, trend analysis, reporting, rule tuning and continual service improvement, while working within a structured incident response lifecycle. This … call requirement. What this role is and is not This role is: A hands-on SOC analyst position focused on live monitoring, investigation and response An onsite role within a 24/7 secure operations environment A role suited to individuals who enjoy operational security, teamwork and threat monitoring ...

Cyber Security Operations Manager

Hiring Organisation
Zachary Daniels Recruitment
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Permanent
Salary
£70000 - £75000/annum Benefits
threat landscape. This is a high-impact position where you'll lead the security operations function end-to-end, driving improvements across threat detection, incident response, and overall security posture within a complex, evolving environment. The Role You'll take ownership of security operations, ensuring the business … capability. Key responsibilities include: · Leading the day-to-day operations of the Security Operations function, including oversight of any outsourced SOC · Managing the full incident response lifecycle (detection through to recovery and post-incident review) · Overseeing threat detection, vulnerability management, and cyber defence capabilities · Driving improvements across ...

Principle IT Security Specialist

Hiring Organisation
Robert Half
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £105,000 per annum
evolve the position based on their strengths and expertise. The successful candidate will play a key role in strengthening security posture through SIEM ownership, incident response, and system hardening, directly contributing to Europe's technological sovereignty. The Role The IT Security Specialist will: Design, build, and operate … centralised SIEM platform to aggregate and analyse security logs across infrastructure, networks, and applications Own security log analysis, vulnerability management, and incident investigation, including defining baselines and developing alerting rules for critical events Lead incident response efforts, using log correlation and analysis to investigate and resolve security ...

Security Operations Analyst

Hiring Organisation
Anson Mccade
Location
North West London, London, United Kingdom
Employment Type
Permanent, Work From Home
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Head of IT Service Management

Hiring Organisation
Deerfoot Recruitment Solutions Limited
Location
Hertfordshire, Hatfield, United Kingdom
Employment Type
Permanent
Salary
£110000 - £130000/annum + 30% Bonus + 7% Pension + More
business performance. Based in Hertfordshire (hybrid), you'll lead end-to-end service management across IT, logistics, fulfilment, and customer operations - owning major incident response, service performance, and continuous improvement at scale. Key responsibilities Lead end-to-end IT service management (incident, problem, change, release, configuration) aligned … ITIL 4 Own major incident management (P1/P2), acting as the senior escalation point with clear executive communication Drive root cause analysis and continuous improvement using service metrics (MTTR, trends, backlog) Oversee IT service delivery, 24/7 support operations, and ITSM tooling Coordinate cyber incident response ...

Cyber Security Manager

Hiring Organisation
Total IT Technology Solutions Ltd
Location
Bedford, Bedfordshire, South East, United Kingdom
Employment Type
Permanent
Salary
£45,000
delivery of cyber security across Total IT not just the strategy, but the execution. You will take full accountability for client security roadmaps, incident response, technical controls, and the day today running of our cyber capability. This role blends hands - on technical leadership with operational delivery. Youll … person who ensures this gets done. Responsibilities: Own client cyber security roadmaps: creation, prioritisation , scheduled review, and delivery. Lead and continually improve our incident response function including triage, containment, communications, and lessons learned. Drive remediation by working closely with Service Desk, Projects, and clients. Maintain robust security reporting ...

Junior SOC Analyst

Hiring Organisation
Searchability NS&D
Location
Farnborough, Hampshire, England, United Kingdom
Employment Type
Full-Time
Salary
£40,000 - £50,000 per annum
security alerts, intrusions, and unauthorised activity Responding to incidents in line with defined SOC playbooks Escalating complex or high-risk incidents to Tier 2 Incident Response teams Reviewing vulnerability scan results and feeding findings back to technical teams Supporting secure configuration reviews and remediation activities Producing regular service … Junior SOC Analyst essential skills A qualification in Cyber Security, Computer Science, Networking, or a related technical discipline Strong interest in cyber security and incident response Understanding of core security concepts and common cyber threats Ability to follow processes, investigate alerts, and document findings clearly Willingness to work ...

Cyber Security Manager

Hiring Organisation
Ashdown Group
Location
Lincoln, Lincolnshire, East Midlands, United Kingdom
Employment Type
Permanent
Salary
£65,000
across the business. The Role Youll lead day-to-day cyber security operations, working closely with IT and business stakeholders to ensure robust monitoring, incident response, and risk management processes are in place. This is a hands-on role with both operational and strategic elements. Key Responsibilities Overseeing … cyber operations, including threat monitoring and incident response Managing vulnerabilities and supporting remediation activities Supporting the development and delivery of cyber security strategy Collaborating with internal teams and third-party providers Driving awareness, training, and continuous improvement initiatives About You Experience in cyber security operations, SOC, or incident ...

Cyber Security Engineer

Hiring Organisation
Womble Bond Dickinson
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Work From Home
endpoint, email, identity, network, cloud and application layers. Manage and integrate a broad ecosystem of third-party cyber security platforms, including managed detection and response services, email security gateways, vulnerability management tools, privileged access management and threat intelligence services. Lead and support cyber security incident response activities … including investigation, containment, remediation and post incident review. Oversee security monitoring, alerting and response processes, working closely with managed service providers where applicable. Conduct and coordinate vulnerability assessment and remediation activities across infrastructure, endpoints, applications and cloud services. Support regulatory, client and internal audits (e.g. ISO 27001), including ...

Principal Cyber Security Engineer

Hiring Organisation
Hays Specialist Recruitment Limited
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
intelligence review), Microsoft Defender for Endpoint and Defender for Cloud, and Darktrace, including system and model tuning, email module management, and configuration of autonomous response actions. You will be responsible for incident response activities, including triaging security alerts, investigating incidents, coordinating escalation and remediation, and conducting root … works closely with the Security Operations Centre (SOC) partner, supporting the assessment and investigation of alerts and contributing to the development and refinement of incident response plans and playbooks. You will support vulnerability management activities, including vulnerability assessments, annual audits, and penetration testing. This includes preparing and presenting ...

Cyber Security Lead

Hiring Organisation
Infoplus Technologies UK Ltd
Location
Sheffield, South Yorkshire, Yorkshire, United Kingdom
Employment Type
Contract
Contract Rate
From £500 to £550 per day
Security: Drive the secure design and operation of critical technology platforms, collaborating with platform owners and engineering teams to embed security throughout the lifecycle. Incident Response & Threat Management: Provide technical oversight for incident response, threat detection, and vulnerability management. Lead root cause analysis and remediation ...

Information Security Manager

Hiring Organisation
Protein Works
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Permanent
DDoS protection to keep our platform secure and performant. Drive vulnerability management across cloud infrastructure and application code, ensuring timely prioritisation and resolution. Lead incident response coordinate detection, investigation, containment and post-incident reviews. Maintain and evolve security monitoring, alerting and operational runbooks to ensure consistent coverage. … familiarity is important. Practical understanding of UK GDPR, DPA 2018 and PCI-DSS compliance requirements. Experience building or maturing security governance policies, risk registers, incident response procedures. Ability to communicate security risk and posture clearly to both technical teams and senior leadership. Hands-on comfort with security tooling ...

Cyber Security & Assurance Engineer

Hiring Organisation
Leidos Innovations UK Limited
Location
Huntingdon, Cambridgeshire, East Anglia, United Kingdom
Employment Type
Permanent
cyber assurance integrates Knowledge of methodologies (Waterfall, Incremental, SAFE, DevOps) Experienced in managing ITHC activities end-to-end, from initial scoping through remediation Incident Response & Awareness Experienced in developing and managing Cyber Incident Response capabilities, including planning, implementation, and continuous improvement Proven experience designing and delivering ...

DevOps Engineer

Hiring Organisation
Peregrine
Location
Gateshead, Tyne and Wear, North East, United Kingdom
Employment Type
Permanent
integration and performance testing for all components Ensure solutions are reliable, reproducible and stable across releases Support continuous improvement of testing practices Monitoring and Incident Response Implement observability and monitoring tooling Track system performance and detect anomalies Support incident response, troubleshooting and root cause analysis ...

Dev Ops Engineer

Hiring Organisation
Peregrine
Location
Newcastle upon Tyne, Tyne & Wear, United Kingdom
Employment Type
Permanent
Salary
£1/annum
integration and performance testing for all components Ensure solutions are reliable, reproducible and stable across releases Support continuous improvement of testing practices Monitoring and Incident Response Implement observability and monitoring tooling Track system performance and detect anomalies Support incident response, troubleshooting and root cause analysis ...